CVE-2022-0204
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 1.8%
exploitation probability
1.8%top 23% of all CVEs
observed exploitation
nono source reports it
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · bluezReferences
https://bugzilla.redhat.com/show_bug.cgi?id=2039807https://github.com/bluez/bluez/commit/591c546c536b42bef696d027f64aa22434f8c3f0https://github.com/bluez/bluez/security/advisories/GHSA-479m-xcq5-9g2qhttps://lists.debian.org/debian-lts-announce/2022/10/msg00026.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00022.htmlhttps://security.gentoo.org/glsa/202209-16